An interactive incident scenario — could you stop it?
BREACH CLOCK
00:00:00
Incident Progression
1
Entry
2
Spread
3
Detection
4
Response
5
Recovery
Situation Briefing
It started with a ChatGPT prompt. Now your network is compromised.
This is a real scenario playing out at companies like yours right now. You will make 5 decisions as the person in charge. Every choice has consequences — and a cost.
At the end you will see exactly what it cost, what stopped the bleeding, and what would have prevented it entirely.
60%
OF BREACHES INVOLVE A HUMAN ELEMENT (VERIZON DBIR 2025)
$10.22M
AVERAGE COST OF A US DATA BREACH (IBM 2025)
241
DAYS AVERAGE TO IDENTIFY AND CONTAIN A BREACH (IBM 2025)
Your Role
You are the VP of Operations at Meridian Group — a 340-person professional services firm. It is 8:47 AM on a Tuesday. Your CISO just sent you a message that made your stomach drop.
DAY 0 — 8:47 AM // STAGE 1: ENTRY
The Message Nobody Wants to Get
INCIDENT ACTIVE
FROM: J. MARCUS, CISO — 8:47 AM
"We have a problem. Three of our account managers have been using ChatGPT to summarize client contracts and proposals. One of them pasted a document containing client PII and internal pricing data into a shared GPT workspace. That workspace was public. We don't know how long it's been exposed or who has seen it. I need a decision on how we respond — now."
The AI tool your team was using had no data classification policy. No one told employees what could and couldn't go into it. This has been happening for 4 months. You have clients in financial services and healthcare. GDPR and HIPAA obligations may apply.
What is your first move?
Decision Consequence — Stage 1
DAY 1 — 11:20 AM // STAGE 2: SPREAD
It Gets Bigger
ESCALATING
FROM: IT SECURITY TEAM — 11:20 AM
"Update: the exposed workspace contained 47 documents over the past 4 months. Client names, SSNs from onboarding forms, one complete financial model. We also found something else — someone accessed the workspace from an IP in Eastern Europe 11 days ago and downloaded 3 files. This may no longer be just an accidental exposure. We may have an active threat actor."
Your threat just escalated from accidental data leak to potential targeted exfiltration. The attacker had 11 days of access. You don't know if they are still in your environment or if the AI tool was a pivot point into your network.
How do you handle the threat actor finding?
Decision Consequence — Stage 2
DAY 3 — 2:15 PM // STAGE 3: DETECTION
What They Actually Found
🔍 INVESTIGATION ACTIVE
FROM: SECURITY INVESTIGATOR — 2:15 PM
"Confirmed: the threat actor used credentials harvested from the leaked documents to authenticate into your client portal. They have been inside for 9 days. We found a dormant backdoor installed on two servers. No ransomware deployed yet — this looks like a reconnaissance and staging operation. They are still here. We can remove them cleanly but we need your call on whether to do it quietly or notify clients and regulators first."
You have an active intruder who has been in your environment for 9 days. They have not deployed ransomware yet. Your security team can remove them. But HIPAA and state breach notification laws may require you to notify within 72 hours of discovery — a clock that started when your CISO first told you about the leak.
How do you proceed?
Decision Consequence — Stage 3
DAY 5 — 9:00 AM // STAGE 4: RESPONSE
The Client Call
📞 CLIENT ESCALATION
FROM: HARTWELL FINANCIAL (CLIENT) — 9:00 AM
"We received your breach notification. We need a call today. Our board is asking questions. We want to know: what data of ours was accessed, when you knew, and what you are doing to ensure this never happens again. We have a vendor review meeting in two weeks and I want to be honest — this is going to be discussed."
Your largest client — $2.3M annual contract — wants answers. They are not threatening to leave yet. But your response in the next 48 hours will determine whether this becomes a retention crisis on top of a security incident.
How do you handle Hartwell Financial?
Decision Consequence — Stage 4
DAY 14 — 10:30 AM // STAGE 5: RECOVERY
The Rebuild Decision
THREAT CONTAINED
FROM: J. MARCUS, CISO — 10:30 AM
"Threat actor is out. Backdoors removed. Environment is clean. Now we need to talk about what comes next. We have three options for hardening our posture. I need budget approval and your direction on which path we take — the board wants a remediation plan by end of week."
The immediate crisis is over. Now comes the decision that determines whether this happens again. Your CISO has laid out three approaches. The difference between them is cost, speed, and how completely they close the gaps that caused this.
Which recovery path do you approve?
Decision Consequence — Stage 5
📄 Get Your Full Incident Report
Enter your details to unlock your complete debrief — including your total incident cost, every decision scored, and a personalized action plan for your organization.
No spam. Your data is never sold or shared. sample privacy language — yours applies on your instance. A security advisor may follow up.
Incident Debrief —
TOTAL INCIDENT COST
DECISIONS SCORED
DAYS TO FULL RECOVERY
What This Means For Your Organization
Sample vendor lineup — configured to your line card
CISCO
CROWDSTRIKE
RUBRIK
VEEAM
BEYONDTRUST
COMMVAULT
AWS
MICROSOFT
A Apex engineer walks through your scenario results and shows how co-managed security — 24×7 SOC, continuous incident response — changes the outcome. No pitch, just answers.
Apex Technology Partners · Sample Brand · Powered by ELO ConsultingScenario modeled on documented 2024–2026 incidents · CONFIDENTIAL